Security

Posted in: Newsmag
Post count: 28

My service provider has notified me that I have these vulnerabilities on my site.

Could you provide an update?
Thank you.

wp-content/plugins/td-composer/legacy/common/common.php {HEX}Malware.Expert.php.base64.decode.UNOFFICIAL

wp-content/plugins/js_composer/assets/lib/vendor/node_modules/bootstrap3/dist/js/bootstrap.min.js SecuriteInfo.com.End-Of-Life-found-in-Bootstrap.UNOFFICIAL

Post count: 9544

I don’t work here, but looks like site has been hacked. You likely want to do clean install of WordPress, all plugins and theme files, backup database, etc.

Post count: 20685

Hi,

Actually we had a few other reports concerning this file wp-content/plugins/td-composer/legacy/common/common.php
Its a security module called CPGuard which flags a part of the code from that file from the composer. It’s a false positive however, we checked those cases and the code in the file was as it should be. The solution was to whitelist the file or path https://opsshield.com/help/cpguard/whitelist-files/ We will however check more to see if we can modify the code in the file so it doesn’t trigger security rules.

I’m not sure about WPBakery however. You could install the latest version for it https://cdn.tagdiv.com/wp-content/uploads/2025/10/js-composer-8.6.1.zip Seems they made security improvements in a recent update https://kb.wpbakery.com/docs/preface/release-notes/

Thanks.

Viewing 3 posts - 1 through 3 (of 3 total)
You must be logged in to reply to this topic.